Skip to content

Troubleshooting

Cloudflare Error 1010: Banned Based on Your Browser's Signature

Cloudflare error 1010 comes from Browser Integrity Check. What it looks for, what an HTTP client should send, and what only the site owner can change.

By 4 min readPublished Updated

Cloudflare error 1010, “The owner of this website has banned your access based on your browser’s signature”, means the site’s Browser Integrity Check refused your request. The check is on by default; it “looks for common HTTP headers abused most commonly by spammers and denies access to your page”, and “challenges visitors without a user agent or with a non-standard user agent”. For an HTTP client, the fix is to send a real, consistent User-Agent with ordinary headers. Beyond that, only the site owner can change it, by turning the check off or skipping it for some paths.

Only automate sites you are allowed to: your own, a client’s, or one whose terms permit it. See responsible captcha automation.

What Browser Integrity Check looks at

Cloudflare’s documentation for error 1010 (checked 1 October 2026) gives the cause as “A website owner blocked your request based on your client’s web browser.” The feature behind it is Browser Integrity Check, and Cloudflare describes it in two sentences:

  • It “looks for common HTTP headers abused most commonly by spammers and denies access to your page.”
  • It “also challenges visitors without a user agent or with a non-standard user agent such as commonly used by abusive bots, crawlers, or visitors.”

Cloudflare does not publish which headers it looks for, or what counts as a non-standard user agent. So a request can meet the check in two ways: a refusal with error 1010, or a challenge page.

A separate Cloudflare product points the same way. Bot Management’s documentation says “Requests with a missing or empty User-Agent header are immediately assigned a bot score of 1”, the score for a request Cloudflare is “quite certain” was automated. That is a different feature from Browser Integrity Check, with its own rules, but both treat a missing user agent as a strong signal.

What an HTTP client sends by default

Your HTTP library sends headers of its own unless you set them. Print what it sends before you guess. In Python with requests:

import requests
print(requests.Session().headers)

With requests 2.32.5 on our machine, that printed a User-Agent of python-requests/2.32.5, an Accept of */*, and two other headers. Whether Cloudflare counts a library’s own user agent as non-standard isn’t documented, but it is not a browser’s. With curl, curl -v prints each request header on a line that starts with >:

Terminal window
curl -sv -o /dev/null https://example.com/ 2>&1 | grep '^> '

What to send instead

  • A real User-Agent, never an empty one. Use the user agent of the browser you actually run, or, for an HTTP client, one you send deliberately and can defend. If you drive a real browser with Playwright or Selenium, leave its own user agent alone.
  • The same user agent for the whole session. Cloudflare lists “a User Agent that changes during the session” among the causes of failed challenges in WebViews, and describes the cf_clearance cookie as “securely tied to the specific visitor and device it was issued to.” Pick one and keep it.
  • Ordinary headers that agree with it. A request that claims to be a browser but sends none of the headers a browser sends is a mixed signal. Set Accept and Accept-Language the way a browser would for the page you request, and don’t invent headers.
  • No forged identities. Don’t claim to be a search engine’s crawler or another verified bot. Cloudflare’s verified bots are ones it has confirmed are “transparent about who it is and what it does”; impersonating one is dishonest, whatever it does to your request.

If you run an honest crawler that names itself in its user agent, the check may still refuse it. In that case the fix is not a disguise but the owner’s exemption, described next.

What the site owner can change

Browser Integrity Check “is enabled by default”. Cloudflare documents three ways for an owner to change it:

  1. Turn it off for the whole zone under Security > Settings, with the Browser integrity check toggle.
  2. Skip it for some traffic with a WAF custom rule using the Skip action.
  3. Turn it on or off for parts of a site with a configuration rule, matching on hostname or URL path.

Cloudflare’s 1010 page sends visitors to the site owner, suggesting a Whois lookup to find a contact, not to Cloudflare. For a partner integration or your own monitor, ask the owner for option 2 or 3 on the paths you use, rather than asking them to turn the check off for everyone.

When the problem is not error 1010

A Cloudflare Turnstile token does not change your client’s signature, so a CAPTCHA solver, ZeroCaptcha included, does nothing for error 1010. If your scraper also submits forms protected by Cloudflare Turnstile, Cloudflare Turnstile for web scraping covers that part, and the httpx tutorial shows a Python client that keeps one session and one set of headers.

Sources

The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.

Questions

What causes Cloudflare error 1010?

The site's Browser Integrity Check refused your request based on your client's signature. The check looks for HTTP headers commonly abused by spammers and challenges clients with no user agent or a non-standard one.

How do I fix Cloudflare error 1010 in Python requests or curl?

Send a real, consistent User-Agent and ordinary request headers, and never an empty User-Agent. If the site still refuses your client, only the owner can change that.

Can the site owner turn off Browser Integrity Check?

Yes. It is on by default and can be turned off under Security > Settings, or skipped for chosen hostnames or paths with a custom rule's Skip action or a configuration rule.

Read next

This article is part of the Cloudflare WAF and 5-second challenge solver hub. Every task is charged only when a token is ready.

Get an API key